---
id: pat-update
title: Update a personal access token
description: Updates one of your personal access tokens. Send only what you want to change.
sidebar_label: Update a personal access token
hide_title: true
hide_table_of_contents: true
api: >-
  eJztWntvGzcS/yoE/2kCrGXZcZJChxRQ0xT1odcGsYP0zjas8e5Yy3qX3JJcyTpD3/0wQ+5qV5JjxUkfd7ggsGWKj3n85kneyQxdalXlldFyJN9XGXh0wmgU5losTG1FhdYZDYWANEXnhDc3qN1AnKDOhNHFQsxz8DRXzEF74Y1Ic9BTHJzrc70nJnhbKYvuEvxEpKDDmtLMUBTg0SairmgRiAWCFdfWlEKb+UCMtQhLs3AmLf7KiysUeOtRZ5gNeP+pBe3dRFisCkjRCSgKot7nGBZ+5USYw/NP5sqnudJTOnTioMRLcJe1QzsRmTWV27aws+oK0hteujr3t5oY5HVhUCgvXG7qIhM5zEgSMpGmQgsk6ONMjmQFflSzuGUiPUydHJ3Jt1tlLS8S6TCtrfILOTq7k1cIFu249rkcnV0sLxJZgYUSPVrHEzSUKEdSZTKRSofTcpmsafs0R1Fr9VuNQmWovbpWaMW1sczJVr0HTiLHmRx5W2MiXZpjCXJ0J/2i4oO1xylauUwk3kJZFShHB4fPjohUWozOf2uyBa1IjfaoPX2EqipUyiLa/9URiXebW5urXzH1MpGVJYF6hY6+DRy3s5y3Sk83OB6L9u8ZClrTshvYkx2CZWFSKPbCfBd4aZC87ahrY0v6RpJS97wqccv5DPmAa2Y0EeBFaZzfxD+pZzUxop/tBsEWiiwHdCbgYTPpcXU4PHy5NzzaG744HQ5H/P9fxFxQ8zbGUNcloTNgWyayazQEzj6TPyLMkCzA1OwNbhCrnk2ltbWofQTWYFcj/JtwOxhhMxKQumK7R/MyaZhZsQvWwmKrjTRkaJy3/uA0x0XjcRqHo/yKN6PRkdyVx9Jtg6/R+PM1G+v6NyvrOpPasr2ZAi9dUU9J2Gu4t/ph2BMTP737qXGKFp2pbYpinqNFHhq/PRY3uPjKCTpLKCfAOTXV6+Axdgpa/ZsR+epgBGlqau1fHYzIllwFKdLoyo5fHZGsV/TvRCrNbGklchpaSOMdaqPtKkfMcbT5RvxkPI7ECaI4e2cKdBdP9jOTun2ofW5spHyfdnVPeX1pLAqlr83gXH+zhpkSCG04SpVcLhPplefhgAHa/oR4WiY761Bl/80aVNkWF7+N0uPv/grqezkcPjt4+fL5i+26O8521BykdKj7wpprkwXBwqb0wXy6poLjDvTt4sri3J4aSliIlFwY+FYdiZgrn5MD11CSw+Uoo5ynzyT+wbnWdVFUBXiKeyK1yJkjBJVXVs3AY6NxOiYFaxe0HG8h9cWCvnAtRT39/9PUq0wxCikSTmlmGhMryj9rH8gGz1KmjNVhcT3iY8kJ0660KDdFRoMWE1EVtWsnMGEKM3G1YNrDGSSUgFvOTXUrLd6iBdu6e48g6OY9Z928ZmQRMtZMVZhFidqPguTkxSZKx1Gxu8FU6Ryt8n8dnJIUWqIeAuebLrhcQsoIYcCK4+8SUaKdYiaU5kLBKT0tcAvSlCMdDc71cTiXs/y5iXpVmgubwI1yQhvP7FFqICCmGbwkx1I4pKTaY7EYnWvlRWVNVqexOKINEzHPVZqLSQNhyLIJp2TtiEXK10LZ43PUArJfa+cH55ogXtaO8zQoCjMP7jFCDiHNRZQdZoHRPgx7tupzPNfMRZpjeiMg8ni1EJPouSeiAucwZC7R+9KxrnXTXLQ0+hoJ0Oc6sBFzVsiyQGMsDllIliiNpQ9bhzE9Sx5vKAm0IRNqGUlBkx6ucMXvpnVtJEutnW2WHBd94zOVY7DNsCCbkBdbPWZrV31U/mDmzFqtSQ7RNPp6cRxqWa0h1PZtD7LsQexHOw9KQyqqhTcVHceV9bYzK2tmKsOB+AeCqyn3hyko7fyqGCfM9X1kjLSPcVsZFshOijwPYfpBpo5bihvXjbdpUROGuMRhcpjjgXhDcG+soeOOV0hbF0AofTRNYE9dOBMgJCZkhTvzuNUPb3ri48aNLYOb5nL9EysHWvQF6oY+vG5wsYNrhym7xZ7X9gglCWMGRb1D5Ux78NT+Lk38l8u+2CrwH0hdHXEzvW+4JGWNrkpb+qIlo1tj31OrLhP5PTuv0KBaFa7tJs3QWtUXibToKqNdoOhwOKRfm7pr2zViDk64mre8rgsSwKObFt2wzd0Z7lu0xXeEVrIqtTviSGSAaBb+CM0j/mMj4u+Uqb8PrZ/j7z7SA+GmTbJjd4WkttFfmaoZ6iYP3KXJUoK7IbYqdbkbupt9ExGW9vcfj8fjW/r39tS9+qJ9jg85ciRrGWtDageW4km/u/GUMhrKRR2bvZnrpmX4pOlcPB18tHGxm/OBKReAJlUEEs7mOxoQb8rKU+MWNUX9HBz70o86ni50STGN69gA31/KJ+3c6PnQhNq2iSYyMxDfGytgvUMV4RYLGItB4R1dKh3Ki05mLOL2pSnZzzdpNjdDB2Icz+VKRhtRGD1FK+bG3lA2jCnUjptqTa/P2HAqUUQpiOJsbYYJRRdjfdTo1irlnmDyiPo+BPCu+J+/ePk1eYw/peY4/OxeRczBBtsbCZ/fytq2fyc7fVQ5z462c/3AgixmLLZEVBYdIa4xdopmMZCETKypViaEqUlTAeyeQ+1a3pIxNpcKnT2vjCkQ9GZWXMxh4cSErhgmHKLgnjuJrixp9jKRZq7RPgYEbE7z3LQi2h62jg6jpvSUfcKjj1p5HEg9uewRmfXmWQU4Tydln3L5QB0auGrEspWak5/3vn4xPBDvT18LWuU8lLH0QN2hjlBDNFAWz7d7WVCJvl8VlL292DsY7g2/Pj04DNnbYBhvGz77KuWTqHeerhTImSo93XYdctBNMdeIzHYA62YuQDE1ru8deA2FI4R2crk/QAAdo79XRxvsdzLMP4hERlg8dlc6+1XHu5jbx+B/9Msvm9n960KRQ0RrjRVtMSCymhsUSs+gUNRrqmpPLrFUjhpOYnXH+sVKAOfB1+61yUh2TI9MZInOwXRLYtWZ/bCv+eH09K0IK0RqMoquMRLEDpdwFabqWqUi7crjCQ6mg0QcDYf044B+PKMfR/209Gg4JBD3abn31jVepOxReCCHFM9iujjjScHjlBr8MY45tDO6iwZV1HYtv7uC7DLmTWykLLYdiLiyCq8Tkdcl6BUlnVmNYw7E0XaNNM7lt5CJd+HQc0kD73VzJ4HZuVzL2TuzuaSJGn2YyCxT9BEKkaEHVTgBV3yN2pDVP+d0lUKy/ZRQkFmG9JAQCkpz2zRAuovgphh+vs1CToL41y1E6YxxHu4DlHM1crMqXiY46kj9b5mG6woiguE5mcbz4SH9eNZX/PM/zyqIWauhuAyTLoPI/jD7OI7HiwidNzQnWAqNqBTFew0zUJyQbBjM1uW/q+mMtag13laYUpYXWDIpt+GygXhbIDgU3i5CYzX0wBurYbp8buI7npSe1vALm5Hcr8Dv36lsSe0D5iW8yKltIUcy975yo/19qNSge302SE0pl51nPidkIwHa3cc+rRBoIxkf3rBP5EkyiR++b2Lz3z+ccoQk23u3enjzphFD+1So34ZJdmjDJfd02VYV91m8enrMnXOv0updxCefvysl652i7lM27NwH7176PHhC9/pu251FryrkK4Xt7flVd/6e1vZF+9Ys9mlCz6VtuXSaJxd8fXdtuLGK1gUzOxgMB0O5SrnG3Yt5MtjKOF+C7kArPCq8r3pbN+TOi7D/P0f8PZ8jRk/i8dbvVwUo1h67qbvozM7ot0zkKDxbyY3zNHh3dwUO39tiuaTh32q09CzxgkBkVag3z+5kphx9zmLJ8xE1P3kX4/5T8egniVu5afonetFBuEwi8lUWQJ4jZGg7JvE6ULZ3SstXCzdyGbLrsGKcplj5j8696MSMt+PT1z+Qs45vIEtOGKSFOXkomAcqTdWaPI/dyQL0tOZoKMOm5NqhHxnWIkH30rQvh7u7MOOUhLhctmIJVkkXXcv/ANmSRO0=
sidebar_class_name: patch api-method
info_path: docs/api/authorization
custom_edit_url: null
canonical: 'https://docs.nullplatform.com/docs/api/pat-update'
---
<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Update a personal access token"}
>
</Heading>

<MethodEndpoint
  method={"patch"}
  path={"/pat/{id}"}
  context={"endpoint"}
>

</MethodEndpoint>

Updates one of your personal access tokens. Send only what you want to change.

- `expires_at` can only move later, up to a year from now. An expired token can't be extended.
- `grants` replaces all of the token's grants.
- Switching to `same_as_user` drops the token's grants. Switching back to `grants` requires the grants it should have.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={[{"name":"id","in":"path","description":"The unique identifier for the personal access token.\n","required":true,"schema":{"type":"integer"},"example":1234}]}
>

</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"A descriptive name for the token.","example":"local-scripts"},"expires_at":{"type":"string","format":"date-time","description":"A later expiration, at most a year from now. The expiration can't move earlier, and an expired token can't be extended.","example":"2027-04-06T00:00:00Z"},"access":{"type":"string","enum":["grants","same_as_user"],"description":"Leave it out to keep the token's current access. `same_as_user` drops the token's grants; switching back to `grants` requires `grants`.\n","example":"same_as_user"},"grants":{"type":"array","description":"The token's new grants. They replace all of its current ones.","items":{"type":"object","oneOf":[{"type":"object","required":["nrn","role_slug"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the API key's role is assigned.","example":"organization=1:account=1:namespace=1:application=4"},"role_slug":{"type":"string","description":"The slug of the role assigned to the API key for this NRN.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n>\n","example":"machine:ci"}},"title":"grantsRoleSlug"},{"type":"object","required":["nrn","role_id"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the API key's role is assigned.","example":"organization=1:account=1:namespace=1:application=4"},"role_id":{"type":"integer","description":"The ID of the role assigned to the API key for this NRN.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n>\n","example":700317756}},"title":"grantsRoleId"},{"type":"object","required":["nrn","actions"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=1:namespace=1"},"actions":{"type":"array","description":"The actions the API key may call at this NRN, without naming an existing role.\nnullplatform creates a role private to the key carrying exactly these actions.\n\n> Note: You can only grant actions you could hand out at that NRN yourself: the ones\n> you hold there, plus the ones carried by roles you may assign to an API key there.\n>\n","items":{"type":"string"},"example":["application:read","deployment:create"]}},"title":"grantsActions"},{"type":"object","required":["nrn","inherits"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=1"},"inherits":{"type":"array","description":"Existing roles, by slug or ID, merged into a single role private to this key.\nInheriting two roles in one grant is not the same as granting them separately:\nit produces one role, which `actions.add` and `actions.remove` can then adjust.\nYou must be allowed to assign each inherited role to an API key at this NRN, the\nsame check a grant by `role_id` passes. The key follows the roles it inherits: an\naction later added to one of them reaches the key too.\n\n> Note: A role private to another API key cannot be inherited.\n>\n","items":{"oneOf":[{"type":"string"},{"type":"integer"}]},"example":["ops","developer"]},"actions":{"type":"object","description":"How the union of the inherited roles is adjusted.","properties":{"add":{"type":"array","description":"Actions granted on top of what the inherited roles provide. Measured against what you can hand out at this NRN.","items":{"type":"string"},"example":["application:delete"]},"remove":{"type":"array","description":"Inherited actions excluded from this grant. Each must be carried by one of the inherited roles, and none may also be in `add`.","items":{"type":"string"},"example":["deployment:create"]}}}},"title":"grantsInherits"}]}},"tags":{"type":"array","description":"The token's new tags. They replace all of its current ones.","items":{"type":"object","properties":{"key":{"type":"string","description":"Tag key.","example":"team"},"value":{"type":"string","description":"Tag value.","example":"platform"}}}}},"title":"patWrite"},"examples":{"Extend the expiration":{"value":{"expires_at":"2027-04-06T00:00:00Z"}},"Follow your access":{"value":{"access":"same_as_user"}}}}}}}
>

</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"The operation was successful.","content":{"application/json":{"schema":{"type":"object","required":["id","name","access","tags","grants","expires_at","created_at","updated_at"],"properties":{"id":{"type":"integer","description":"Unique ID for the token.","example":1234},"name":{"type":"string","description":"The descriptive name given to the token.","example":"local-scripts"},"masked_api_key":{"type":"string","description":"The token, masked.","example":"AAAAxxxxxPTs="},"access":{"type":"string","enum":["grants","same_as_user"],"description":"Whether the token follows your access (`same_as_user`) or holds its own grants (`grants`).","example":"same_as_user"},"tags":{"type":"array","description":"Tags associated with the token. Empty when it has none.","items":{"type":"object","required":["key","value"],"properties":{"key":{"type":"string","description":"Tag key.","example":"team"},"value":{"type":"string","description":"Tag value.","example":"platform"}}}},"grants":{"type":"array","description":"What the token can do. For a `same_as_user` token, these are your own grants in the organization at the moment of the request. A token that no longer works, because it expired or your user is inactive, reports none.\n","items":{"type":"object","properties":{"id":{"type":"integer","description":"The ID of the grant.","example":5678},"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=2"},"role_id":{"type":"integer","description":"The ID of the role granted.","example":700317756},"role_slug":{"type":"string","description":"The slug of the role granted.","example":"developer"},"actions":{"type":"array","description":"The action names the grant resolves to, present when it was created from `actions` or `inherits`.","items":{"type":"string"},"example":["application:read","deployment:create"]}}}},"personal":{"type":"boolean","description":"Always `true` for a personal access token.","example":true},"owner_id":{"type":"integer","description":"The ID of the user who created the token.","example":42},"acting_user_id":{"type":"integer","description":"The ID of the user the token acts as: you.","example":42},"last_used_at":{"type":"string","format":"date-time","nullable":true,"description":"The ISO-8601 UTC timestamp of when the token was last exchanged for an access token.","example":"2026-10-08T12:00:00.000Z"},"expires_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token stops working.","example":"2027-01-06T00:00:00.000Z"},"expired":{"type":"boolean","description":"Whether the token has expired.","example":false},"created_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was created.","example":"2026-10-08T00:00:00.000Z"},"updated_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was last updated.","example":"2026-10-08T00:00:00.000Z"}},"title":"patResponse"}}}},"4XX":{"description":"Client error responses due to invalid input or missing parameters.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific client error (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"bad_request"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Bad Request\", \"Unauthorized\").","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error (e.g., 500, 502, 503).","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Internal Server Error\", \"Service Unavailable\").","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred. Please try again later."}}}}}}}}
>

</StatusCodes>

